4
CVE-2014-8735
- EPSS 0.22%
- Veröffentlicht 12.11.2014 16:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before 7.x-2.2216 for Drupal logs usernames and passwords, which allows remote authenticated users with the "administer bad behavior" permission to obtain sensitive information by reading a log file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bad Behavior Project ≫ Bad Behavior Version6.x-1.0 Updaterc1 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-1.0 Updaterc2 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-1.x Updatedev SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.1 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2 Updaterc14 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.13 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.14 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.113 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.114 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.115 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.116 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.200 Updaterc14 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.214 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.215 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.216 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.217 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.220 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.221 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.222 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.223 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.225 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.226 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.227 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.228 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2210 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2211 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2212 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2213 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2214 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version6.x-2.2215 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.220 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.221 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.222 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.223 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.225 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.226 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.227 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.228 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2210 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2211 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2212 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2213 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2214 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2215 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.2216 SwPlatformdrupal
Bad Behavior Project ≫ Bad Behavior Version7.x-2.x Updatedev SwPlatformdrupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.412 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.